Splunk Search

Fields for multiple sourcetype

vaibhavagg2006
Communicator

Hi,
I wanted to know what is the best technique used for creating fields for multiple sourcetypes.
For example if i have 4 sourcetype named
st1,st2,st3,st4
I want to extract a field which displays errros.
So shall I create duplicate fields for each sourcetype or there is some better method available.

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Yes, you will have separate fields extractions for each sourcetype. If st1, st2 etc are all the same format then you'd combine them into a single sourcetype.

You could define an eventtype to have a nice way to search across all of those sourcetypes for specific errors.

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Defineeventtypes

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...